Threat Intelligence Directory

Database of identified threat actors, APT groups, malware families, and ransomware operations. Tracking attribution, motivations, technical capabilities, and operational patterns.

8,800+ entities tracked — APT groups, malware families, ransomware operators

10,719 entities
APT GROUPespionageadvanced
ROLLCOAST is a ransomware program that encrypts files on logical drives attached to a system. ROLLCOAST is a Dynamic Linked Library (DLL) with no named exports. When observed by Mandiant it uniquely had only one ordinal export 0x01. This suggested the sample was designed to avoid detection and be invoked within memory, possibly through BEACON provided to affiliates. Incident responders working on similar intrusions should capture memory for analysis.
APT GROUPespionageadvanced
It is a backdoor commonly distributed as an encoded binary file downloaded and decrypted by shellcode following the exploitation of weaponized documents. DOGCALL is capable of capturing screenshots, logging keystrokes, evading analysis with anti-virtual machine detections, and leveraging cloud storage APIs such as Cloud, Box, Dropbox, and Yandex.
APT GROUP
Malware family tracked by Malpedia. ID: win.rokku
APT GROUP
A .NET variant of ps1.roguerobin
APT GROUP
Malware family tracked by Malpedia. ID: win.rofin
Updated: 2016-04-20
View profile →
APT GROUP
Malware family tracked by Malpedia. ID: win.rockloader
APT GROUP
Malware family tracked by Malpedia. ID: win.rock
Updated: 2018-09-19
View profile →
APT GROUPfinancial
RobbinHood is a ransomware group first observed in April–May 2019, responsible for high-profile attacks on US cities including Baltimore, Maryland — demanding 13 BTC and causing months of disruption to city services — believed to operate as a limited closed-circle model rather than a broad public affiliate program.
Infra: 🔗 robinhoodleaks.tumbl
RLUpdated: N/A
View profile →
APT GROUP
According to SOCRadar, this is a batch script that uses WinRAR to delete files with target file extensions from a disk.
APT GROUP
Malware family tracked by Malpedia. ID: win.roadsweep
APT GROUP
CyberInt states that Remote Manipulator System (RMS) is a legitimate tool developed by Russian organization TektonIT and has been observed in campaigns conducted by TA505 as well as numerous smaller campaigns likely attributable to other, disparate, threat actors. In addition to the availability of commercial licenses, the tool is free for non-commercial use and supports the remote administration of both Microsoft Windows and Android devices.
APT GROUP
Created from the codebase of Gozi/ISFB.
APT GROUP
Malware family tracked by Malpedia. ID: win.rising_sun
APT GROUP
RisePro is a stealer that is spread through downloaders like win.privateloader. Once executed on a system, the malware can steal credit card information, passwords, and personal data.
APT GROUP
RiseLoader is a new malware loader family first observed in October 2024. It uses a custom TCP-based binary network protocol similar to, but distinct from, that used by the PrivateLoader and RisePro malware families. RiseLoader often drops other malware families, such as Vidar, Lumma Stealer, and XMRig, as secondary payloads. It collects information about installed applications and browser extensions, likely related to cryptocurrency. Key technical characteristics of RiseLoader include: Anti-analysis Techniques: Samples are often packed with VMProtect and obfuscate strings related to malware analysis and debugging tools. Behavioural Analysis: Creates a mutex with a hardcoded prefix and randomly generated suffixes. Communicates with a C2 server over TCP using a custom protocol involving specific message types for tasks such as transferring system information, receiving payloads, and confirming execution. Downloads and executes payloads from URLs provided by the C2 server. Creates registry keys as infection markers. Network Communication: Uses a custom TCP-based protocol with message types like SEND_VICTIM_INFO, SYS_INFO, PAYLOADS, KEEPALIVE, and others. Data is XOR encoded using keys exchanged via a SET_XORKEYS message. The protocol includes a three-way handshake and mechanisms for re-establishing connections. Similarities to RisePro/PrivateLoader: Shares similar network communication protocols and message structures with RisePro and PrivateLoader suggesting a potential link between their developers, though RiseLoader's protocol appears simplified. It currently lacks RisePro/PrivateLoader's information-stealing features but may be under development.
APT GROUP
Malware family tracked by Malpedia. ID: win.ripper_atm
APT GROUP
Malware family tracked by Malpedia. ID: win.rincux
APT GROUP
Malware family tracked by Malpedia. ID: win.rikamanu
APT GROUP
Malware family tracked by Malpedia. ID: win.rifdoor
APT GROUP
Rietspoof is malware that mainly acts as a dropper and downloader, however, it also sports bot capabilities and appears to be in active development.
APT GROUPfinancial
Rhysida is a ransomware-as-a-service (RAAS) group that emerged in May 2023. The group utilizes a namesake ransomware through phishing attacks and Cobalt Strike to breach the targets' networks and deploy their payloads.<br> <br> The group threatens to publicly distribute exfiltrated data if the ransom is not paid, and it's worth mentioning that Rhysida is still in the early stages of development.<br> <br> The ransomware leaves PDF notes in the affected folders, instructing victims to contact the group through its portal, and payment is made via Bitcoin.<br> <br> After encryption, the ransomware appends the extension '.ryshida' to encrypted files.<BR>Source: https://github.com/crocodyli/ThreatActors-TTPs
Infra: 🔗 rhysidafohrhyy2aszi7🔗 rhysidafohrhyy2aszi7🔗 rhysidafohrhyy2aszi7+4 more
RLUpdated: 2026-08-04
View profile →
APT GROUP
Malware family tracked by Malpedia. ID: win.rhttpctrl
APT GROUPfinancialhigh
Ransomware.
APT GROUP
According to PCrisk, Rhadamanthys is a stealer-type malware, and as its name implies - it is designed to extract data from infected machines. At the time of writing, this malware is spread through malicious websites mirroring those of genuine software such as AnyDesk, Zoom, Notepad++, and others. Rhadamanthys is downloaded alongside the real program, thus diminishing immediate user suspicion. These sites were promoted through Google ads, which superseded the legitimate search results on the Google search engine.
APT GROUP
Malware family tracked by Malpedia. ID: win.rgdoor
APT GROUPfinancial
Sodinokibi ransomware group also known as REvil (Ransomware Evil) operates as a ransomware-as-a-service (RaaS) model. After the group compromised his victims, they would threaten to publish the victim's sensitive data on their darknet blog named 'Happy Blog', unless the ransom is paid. The ransomware malware code used by REvil is pretty similar to the ransomware code used by DarkSide - a different threat actor. REvil group claims to steal information after a successful attack on the supplier of the tech giant Apple and stole confidential schematics of their upcoming products.
Infra: 🔗 dnpscnbaix6nkwvystl3💬 aplebzu47wgazapdqks6🔗 blogxxu75w63ujqarv47+7 more
RLUpdated: N/A
View profile →
APT GROUPfinancialhigh
Ransomware.
APT GROUP
Malware family tracked by Malpedia. ID: win.reverse_rat
APT GROUP
According to Cofense, Revenge RAT is a simple and freely available Remote Access Trojan that automatically gathers system information before allowing threat actors to remotely access system components such as webcams, microphones, and various other utilities.
APT GROUP
According to its author, Revenant is a 3rd party agent for Havoc written in C, and based on Talon. This implant is meant to expand on the Talon implant by implementing covert methods of execution, robust capabilities, and more customization.
APT GROUP
Malware family tracked by Malpedia. ID: win.revc2
APT GROUP
Malware family tracked by Malpedia. ID: win.retro
APT GROUPfinancialhigh
The Android app using for Retefe is a SMS stealer, used to forward mTAN codes to the threat actor. Further is a bank logo added to the specific Android app to trick users into thinking this is a legitimate app. Moreover, if the victim is not a real victim, the link to download the APK is not the malicious APK, but the real 'Signal Private Messenger' tool, hence the victim's phone doesn't get infected.
APT GROUP
Malware family tracked by Malpedia. ID: win.retadup
APT GROUP
According to Cisco Talos, Resident is a backdoor likely developed by the same author as win.warmcookie, and it was observed being delivered in intrusions they attribute to TA866.
APT GROUP
Malware family tracked by Malpedia. ID: win.reshell
APT GROUP
Malware family tracked by Malpedia. ID: win.rerdom
APT GROUP
Malware family tracked by Malpedia. ID: win.remy
APT GROUP
Malware family tracked by Malpedia. ID: win.remsec_strider
APT GROUP
Malware family tracked by Malpedia. ID: win.remotecontrolclient